Command interpreter started PowerShell with encoded arguments
cmd.exe → powershell.exe · usr-fin-610 · asset-ws-610- CONDITION 01
- process_name equals powershell.exe
- CONDITION 02
- attributes.execution_style equals encoded
WORK · I
LOCAL SOC & DETECTION ENGINEERING LAB · 1.0.0
A compact analyst workspace that carries synthetic incidents from raw telemetry through explainable detections, evidence correlation, incident decisions, and professional reports.
01
02
source = sysmon and severity = high192 EVENTScmd.exe → powershell.exe · usr-fin-610 · asset-ws-61003
Every match exposes the field, operator, expected value, and observed value that produced the alert.
Evidence, notes, hypotheses, findings, alert decisions, and incident decisions remain in SQLite.
Expected outcomes stay on the backend until submission, followed by deterministic learning feedback.
A small read-only query language filters in-memory events without passing scenario input to SQL or an evaluator.
04
The advanced SOCWerk-native investigation asks the analyst to reconstruct a multi-stage compromise while separating hostile behavior from credible administrative and business lookalikes.
EMAIL · OFFICE · SYSMON · POWERSHELL · WINDOWS SECURITY · VPN / MFA · DNS · PROXY · ENDPOINT · ZEEK
05
06
The lab does not scan networks, send phishing, generate payloads, execute scenario commands, or contact targets.
All identities, domains, addresses, files, and infrastructure are synthetic; network indicators use reserved ranges and .example domains.
Scenario packs are strict versioned JSON. They cannot load code or remote content, and their expected outcomes remain server-side before submission.
Containment is a documented analyst decision only. It never performs an action against an external system.
SOURCE · ARCHITECTURE · THREAT MODEL